CVE-2026-62829
Microsoft SharePoint Server Spoofing Vulnerability
Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
In plain language
AI Act nowCVE-2026-62829 is a SharePoint Server bug that lets a logged-in user manipulate what other people see in their browser to impersonate someone else; a typical small business should update if they use SharePoint and you have more than one user with accounts.
CVE-2026-62829 is an authenticated spoofing issue in Microsoft SharePoint Server (SharePoint web page rendering) where an authorized user can manipulate browser-rendered content (improper input handling during web page generation) to impersonate other users/entities and trick victims into interacting with fraudulent interfaces.
What to do now
- Check your SharePoint Server version (2019 vs Subscription Edition) in the SharePoint server/update page or via your admin/IT inventory.
- Compare your current version to the fixed versions: 16.0.19725.20522 for SharePoint Server and SharePoint Server Subscription Edition, or 16.0.10417.20198 for Microsoft SharePoint Server 2019.
- Upgrade SharePoint Server to the matching fixed version as listed by Microsoft for CVE-2026-62829.
- If you cannot patch immediately, reduce the chance of abuse by limiting who has SharePoint access (especially any account that could edit or influence SharePoint-generated content) until the update is applied.
- After updating, review for suspicious content changes and unusual links or prompts inside SharePoint pages around the time of the update.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:RUser InteractionS:UScopeC:LConfidentialityI:LIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-62829 and every CVE in our database. Create a free account — no credit card required.
Create Free Account